CVE-2026-13129: Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form object when accessing the field property path. Eventually, the application crashes due to reading an invalid pointer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13129?
The severity of CVE-2026-13129 is rated high with a score of 7.8.
How do I fix CVE-2026-13129?
To fix CVE-2026-13129, ensure you are using the latest version of Foxit PDF Editor or Foxit PDF Reader that addresses this vulnerability.
What type of vulnerability is CVE-2026-13129?
CVE-2026-13129 is identified as a Use-After-Free vulnerability that allows for remote code execution.
What applications are affected by CVE-2026-13129?
CVE-2026-13129 affects Foxit PDF Editor and Foxit Reader.
What can happen if CVE-2026-13129 is exploited?
If exploited, CVE-2026-13129 can lead to application crashes and potentially allow attackers to execute arbitrary code.